ZeroHour

CVE-2026-75940

Hard-coded credentials in Lenovo Health Android app expose health data

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-75940 is a use of hard-coded credentials (CWE-798) in the Lenovo Health Android Application, an app distributed exclusively in the Chinese market. Because the CVSS 4.0 vector shows network attack vector with no privileges or user interaction required, the embedded credentials can be exploited remotely by an attacker without any account access or user involvement. A successful attack exposes sensitive health-related information, and the vector's high integrity impact suggests the attacker may also be able to alter stored health data. Affected users are those who have the Lenovo Health Android app installed on their devices in China. As of now there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported.

What to do: Check whether the Lenovo Health app is installed on managed Android devices and update it to the latest version available through Chinese app stores once Lenovo publishes a fix, since no patched version number is specified in the available data. Because the app is consumer-facing and China-exclusive, enterprise defenders outside China should simply verify no users have sideloaded or installed it. Monitor Lenovo's PSIRT advisory for updated version and remediation details.

Affected
Lenovo Health Android Application (Chinese market)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

Weakness
CWE-798
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.